In dating applications, users typically pay for attention, expecting to interact with real individuals. However, a recent report revealed that in over 20 Chinese dating apps, real profiles were outnumbered by AI personas, with approximately three AI characters for each human account. These AI entities engaged users in conversations, maintained "relationships," and ultimately extracted money from them.

This scenario is just one of many highlighted in a report by Anthropic released on September 10, 2026. The report examines how artificial intelligence is exploited for cyberattacks, data theft, fraud, political manipulation, and even training competing models using other developers' work.

The methods of deception are as old as time. However, while such operations previously required teams of individuals, today, a single person can orchestrate them. Let’s explore some of the most creative schemes identified in the report by the AI model Claude.

A Platform for Lonely Hearts

The operation involves three main categories of participants:

  1. American users who paid for communication.
  2. Part-time workers who were compensated for being "real".
  3. A Chinese IT studio with over 20 app versions, its own servers, and a unique set of characters for each application.

Users' funds were deducted based on a message counter. Conversations and new "matches" consumed message limits, which were replenished using the app's internal currency. The longer the AI maintained a conversation, the faster the user's balance dwindled.

Revenue was funneled away from the app: an embedded browser redirected funds to third-party payment processors. This browser was activated remotely, and the window was concealed during moderation checks by app stores.

To prepare for app store scrutiny, the company created an interface element that only activated during reviews, and varied the names of software classes across the 20+ builds to avoid detection.

The AI models were assigned different roles:

  • "Warm and human-like" Claude handled conversations: 4,700 personas interacted with at least 25,000 users, generating around 2.36 million messages over two weeks in April 2026;
  • A simpler external LLM provided three preset responses for part-time workers, assessed attractiveness from photos, and filtered incoming images and voice messages;
  • An image-processing model created avatars for non-existent conversational partners.

Recruitment was done through invitations, offering payment for each action—chat responses, video calls, and social media follows. The human operators took on tasks that machines often struggle with, such as showing their faces on camera or reciprocating follows. When no part-time workers were available, the system simulated activity by liking posts, showing fake profile visitors, and presenting pre-recorded videos instead of live video calls, while also updating a registry of suspicious users.

Spotting the deception through chat was challenging: the AI responded quickly, recalled details from past conversations, and remained in character. The model treated its task like a role-playing game: there were no instructions regarding payment or the scheme surrounding it, only behavioral guidelines to avoid admitting to users that they were conversing with a program, deflect requests for additional photos or video calls, and progress through predefined "relationship-building" stages.

In some instances, Claude realized it was part of a scam but still generated responses as if it were a fictional partner. Some lonely users shared experiences of serious illnesses, yet the conversations continued as usual.

The report does not specify how much the studio earned; it provides no figures on revenue, user spending, or average transaction amounts—only the volume of conversations observed over the two-week period.

Essentially, the scheme is not novel: fake profiles, activity inflation, and moderation evasion have been around for a while. However, the economics have shifted: previously, managing 20 apps with 4,700 personas would have required a full team, but now a few subscriptions with different roles are sufficient.

        How the network of twenty dating applications operated. Source: Anthropic.

Vibe-Hacking

The term is an ironic reference to vibe-coding, sharing a similar principle but with different objectives.

It operates as follows:

  • The operator sets the task: "Here are the stolen keys, here are the targets, retrieve the data";
  • The model enters the scene—inspects the victim's corporate network, writes and executes scripts, reports findings, and repeats the cycle until the desired result is achieved.

The operator does not need to know how the attacked company's internal infrastructure is structured.

Anthropic draws several conclusions from its observations. Previously, a firm’s complex systems provided a level of protection; understanding an unfamiliar environment required an experienced specialist and several weeks of work. Now, such reconnaissance can be completed in a couple of hours using machines. The assumption that a foreign infrastructure is too complex for outsiders is no longer valid.

Internal model limitations do not always trigger. In one instance, Claude rejected nine out of ten malicious requests. However, the same task was accomplished through indirect means: it was broken down into a series of harmless steps and passed through various sessions.

For the first time, Anthropic described such scenarios in August 2025. At that time, it involved just one individual who attacked at least 17 organizations in a month, demanding ransoms ranging from $75,000 to $500,000 in Bitcoin. The recent report indicates that such operations have multiplied, with some extortionists demanding between $1.5 million and $2.5 million in certain cases.

While no radically new techniques have emerged, the attack economy has changed: what once required a full team and weeks of meticulous work can now be accomplished by a single advanced vibe-coder in a weekend.

A Conveyor of Stolen Secrets

A French-speaking participant in the scheme, known by the pseudonyms MeowSHA, frkoo, and blazespider, established a streamlined operation for collecting stolen passwords. He rented ten cloud servers, downloaded 1.8 million Android app installation files from various catalog sites, and dissected each to hunt for forgotten credentials.

App developers often embed API keys for email, cloud, and payment services directly into the code and frequently forget to remove them before publication.

The program automatically verified the found credentials for functionality and promptly sent them to Telegram, categorizing them by the type of secrets discovered—a total of 471. Simultaneously, the application collected developer credentials.

The speed of hacking with these new tools and approaches is astonishing. In one instance, the time from a stolen token to full cloud takeover for a company was just three hours. In another case, AI agents extracted 2,100 tokens from 40 corporate Microsoft clouds in 34 hours.

The scale of the thefts matches the development pace of new solutions:

  • A technology provider lost over a terabyte of data, including hundreds of thousands of national ID numbers and millions of credit card records;
  • An airline's system was compromised, affecting tens of millions of passenger profiles;
  • Hackers targeting an energy company claimed they could remotely adjust the current at home charging stations for electric vehicles.

The monetization of the stolen data was organized as a separate business. Stolen card data was sold through a store on a domain mimicking the French national police website. A mini-application in Telegram served as a storefront, housing a database with aggregated leaks, including approximately 400,000 records of a telecom operator's customers along with their banking details.

Notably, MeowSHA maintained a dual accounting system. While engaging in extortion, he participated in vulnerability discovery programs and received official rewards for his findings. According to his own statements, two companies among the victims paid him $2,000 and $5,000 for the vulnerabilities he identified in their systems.

However, the hacker struggled with self-discipline. He inadvertently left the address of his own server, keys to his Telegram bots, and proxies with embedded passwords within the compromised infrastructure. He extracted terabytes of data and left behind enough evidence for him to be tracked down due to the digital traces he left behind.

How the password theft conveyor operated. Source: Anthropic.

“Cheap” Claude and Account Factories

A separate market has emerged around access to AI models. A Russian and Ukrainian group led by an individual known as kl1zy sold discounted subscriptions to Claude. They accepted payment and provided access—only for the prompts to be sent to a different, cheaper AI model. The difference went into their pockets.

This group did not stop there. Along with access, customers received malware that extracted credentials from their computers. The acquired data was then sold to other resellers.

Other hacker groups employed similar schemes. They disguised pages as intermediaries between different models and popular tools for developers. The collector remained in the system even after password changes—simply sending new login details.

Another participant, who previously extorted money from hotel chains and fintech companies, shifted his focus to the AI industry. In one vendor's sandbox, he left instructions for the model and used them to gain access to the company's operational keys. He then executed a scripted scenario against 30 AI developers within four days, aiming for access to an unannounced model, which he ultimately could not obtain.

Another "business direction" targeted cryptocurrency platforms, building an account factory from ready-made components:

  • Residential proxies;
  • Anti-detect browsers that obscure digital footprints;
  • Commercial CAPTCHA-solving services;
  • Automated email polling for registration confirmation.

The result was verified accounts on exchanges and marketplaces, created in "batches" and prepared in advance. The report also details a KYC interception scheme: victims were lured to a fake website, their documents and selfies were sent for genuine verification through an intermediary server, while the hacker obtained the finished session along with scans.

In this scenario, identity verification ceases to be a barrier. The exchange sees a real person with valid documents who has completed verification according to all rules—only someone else is using that account.

Who Else Bought Access

Through the same resale infrastructure, access to Claude was also acquired by Chinese AI laboratories—seven in total were reported. Operators associated with Alibaba recorded over 151 million exchanges with the LLM from May to July 2026.

Moonshot provided its clients with Claude's responses under the guise of operating its own model: approximately 300,000 requests over ten days through 5,380 fake accounts. DeepSeek registered 12.1 million exchanges in 14 days.

Zhipu attempted to access Fable but could not breach its defenses. They then switched to Opus 4.6, deeming its barriers to be weaker.

Not only model developers suffered; along with redirected requests, usernames, email addresses, corporate data, and operational access keys were also transmitted. Whether Moonshot and DeepSeek informed their clients where their prompts were actually going remains unspecified in the report.

One Person Acting as Intelligence Services

In spring 2026, a French-speaking hacker targeted European political parties, media outlets, analytical centers, and IT contractors serving these organizations. He had 42 targets in development and gained internal access at the fourteenth. This was a massive operation executed by a single individual.

A custom scanner written in Rust searched open repositories for foreign access keys and immediately verified their functionality. The discovered keys were routed through a local proxy server—this way, his requests to the model blended with the traffic of the actual owner.

Access to the websites was facilitated by a previously unknown vulnerability in WordPress: during the reinstallation of the engine, there was a brief pause during which the attacker could create an administrator account without a password. The program to exploit this flaw and the test setup for it were assembled in one session with the model. The scheme worked on at least four sites.

The operator aimed to maintain a long-term presence in the captured territories:

  • The web shell was hidden among font files;
  • A plugin from the non-disconnectable category collected inputted passwords and encrypted them with a unique key for each site;
  • Backups were infected in such a way that restoring the site returned access to the hacker.

One of the victims was a European platform for managing political campaigns. Through its open search interface, the operator extracted around 140,000 records of voters' political views.

On one publication's site, he deployed a browser command center via an embedded script. This captured the digital fingerprints of thousands of readers, while the scheme organizer hunted for sessions and passwords of editorial staff.

The final product was afsearch—a homemade search engine for deanonymization containing tens of millions of lines, unifying names, phone numbers, and other identifiers. The results were posted on the dark web, with the total volume of extracted databases ranging from 12 to 26 GB.

The entire month-long campaign was funded by others: the costs for model interactions were covered by the owners of the stolen keys, while the operator spent nothing.

All details of this operation are provided solely by Anthropic—no independent verification exists.

Content Factories on Demand

Another aspect of the report examines content factories: networks of fake publications and accounts churning out materials on an industrial scale to influence public opinion.

Most of these operations are blocked by Anthropic before they reach readers. Exceptions occur when generated text leaks into established publications with existing audiences.

The largest network was constructed by the French advertising agency LKM Company. Over ten weeks in mid-2025, it registered domains and launched around 70 news websites on a shared infrastructure. Each of these outlets appeared as a local publication with a full staff. The authors were fabricated along with the articles.

One such publication looked like this:

One of approximately 70 fictitious publications from the LKM Company network. Source: Anthropic.

Each site received its own account on X. An additional layer formed with over 250 commenting accounts, featuring AI-generated photographs. Most of these accounts were created in June and July 2025:

Some of the commenting accounts from the LKM Company network, created in June and July 2025. Source: Anthropic.

The publication of articles became a conveyor belt process. Each request to the model required:

  • A fixed response structure in JSON format;
  • A prepared HTML markup;
  • An exact character limit;
  • Three to four internal links to other materials on the same site.

This standardization allowed the information resources to achieve good positions in search results. The network published at least 8,913 articles in approximately 20 languages for audiences in the USA, Brazil, France, and the Democratic Republic of the Congo.

The project lacked a specific ideology. The tone of the materials depended on who was paying at any given moment. One direction stood out particularly—Congo, where 318 pieces supported the local authorities' stance in the conflict with Rwanda. Anthropic could not ascertain who commissioned this part of the campaign.

The next case involves not a network but a tool that sustained similar schemes. It was sold by the Istanbul-based technology company BBS Bilisim Teknolojileri as a regular paid service. The documentation described the development as "military-grade platforms for real-time political operations driven by artificial intelligence."

Clients received census data and electoral statistics for each district in Malaysia, on which they built voter profiles. Next, a network of approximately a thousand fake accounts and one generated publication—Malaysia Pulse—came into play:

Malaysia Pulse—a fake publication from the Malaysian operation; the domain was registered on May 10, 2026. Source: Anthropic.

The control panel included a parameter to order the desired number of artificial views for each target. In one request, this figure reached a million—for the account of the current Malaysian prime minister.

The operators also fabricated fake intelligence dossiers with made-up accusations against opposition politicians and human rights organizations. The platform developers also sought a contract with the national communications regulator. Whether they succeeded remains unknown.

The platform itself calculated its reach metrics. Anthropic could not independently verify these figures.

Not all such content factories operate on a grand scale. In the Gaibandha district of Bangladesh, a single individual managed the network by running 29 Claude accounts through his own script, fake_news_3.py, for sixteen months. The algorithm delivered content in batches: 15 headlines, three extended stories, and 15 prompts for images at a time. The finished videos were uploaded to YouTube on a schedule set months in advance. In internal correspondence, the author remarked that no one doubted the authenticity of the news.

In Kenya, the network released "portions" of 50 tweets at a time. The model received direct instructions to mask the posts as spontaneous opinions rather than a coordinated campaign. Some posts praised Minister Opiyo Wandayi for canceling tariff increases, while others attacked the opposition coalition ahead of the 2027 elections. The same working template was used for retail brand promotions—just inserting a link into every fifth post.

All these projects resemble conventional businesses. They feature employment contracts with clauses on editorial loyalty, internal lists of prohibited words, and even training courses for new employees.

The schemes involving fictitious foreign brides operated twenty years ago: on the other end was a live operator making a living by simulating flirtation. AI has not reinvented this model; it has simply eliminated labor costs from it.

A similar story applies to fake publications and the hunt for stolen passwords—the mechanics remain the same, but the pricing has changed.

Every new technology follows the same trajectory: first, it is mastered by regular users, and then, very quickly, by fraudsters. This was the case with the internet and mobile communications, and it is happening with LLMs. The only difference is the speed—now the transition from novelty to widespread fraud scheme takes only weeks instead of years.